CVE-2026-94132

Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so anyone who could email the monitored mailbox could write a PHP file into the web root.

  • Published Sep 26, 2026
  • CVSS 9.5 critical
  • 0.6% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-94132 at the National Vulnerability Database